Sign in

Steve Syfuhs

@syfuhs.net
3.8K followers 574 following 14K posts

Noted idiot. Principal something or other. Runs the Windows Authentication team at Microsoft. It's my fault your password doesn't work. Mostly dog pictures. Might actually be two dogs in a trench coat. 🇺🇸 / 🇨🇦 syfuhs.net

PostsRepliesMedia
Steve Syfuhs @syfuhs.net · 6m
static.klipy.com
333вфыв
ALT: 333вфыв
000
Steve Syfuhs @syfuhs.net · 40m
static.klipy.com
Ozzy Osbourne Calls Sharon
ALT: Ozzy Osbourne Calls Sharon
020
Steve Syfuhs @syfuhs.net · 58m
It's the big black one
230
Steve Syfuhs @syfuhs.net · 1h
We're all a little damaged
010
Steve Syfuhs @syfuhs.net · 1h
None of them are, at least including reelection.
100
Steve Syfuhs @syfuhs.net · 1h
Is that a... moognet?
020
Steve Syfuhs @syfuhs.net · 1h
Worst thing I've ever seen. Shame brought to you and your family. Yadda yadda.
000
Steve Syfuhs @syfuhs.net · 17h
In Soviet Russia Vodak drink you
120
Steve Syfuhs @syfuhs.net · 17h
Smart kiddo
120
Steve Syfuhs @syfuhs.net · 18h
All good. A wonderful distraction. Only so many ways to keep busy when people die without going crazy. All things considered I'm all for making a better UX for it. Even all for making a better password manager all up.
040
Steve Syfuhs @syfuhs.net · 19h
static.klipy.com
Jack Black Nodding in Nacho Libre
ALT: Jack Black Nodding in Nacho Libre
120
Steve Syfuhs @syfuhs.net · 19h
How many hobit feets is that
120
Steve Syfuhs @syfuhs.net · 19h
Who knew 1500 feet was YEARS meters
1110
Steve Syfuhs @syfuhs.net · 19h
Cooooooomplicated af to say the least. We've been building out a ton of functionality on this front through MXC as well as Windows internals. github.com/microsoft/mxc It's somewhere between a spiritual successor and vnext of appx.
github.com
GitHub - microsoft/mxc: Policy-driven, layered isolation and containment
Policy-driven, layered isolation and containment . Contribute to microsoft/mxc development by creating an account on GitHub.
010
Steve Syfuhs @syfuhs.net · 19h
Certainly. No argument on that. I'm not convinced there's a way that will happen at "all apps" scale though. That's the crux of my point. Unless that happens there isn't a whole lot we can that is generally usable. It's a painful line to straddle.
110
Steve Syfuhs @syfuhs.net · 20h
This is my point. UWP works the same way (appx). The fact that android doesn't have that third tier of arbitrary app is what allows it to make the promises it can, which makes it an unequal comparison.
210
Steve Syfuhs @syfuhs.net · 20h
You have system executable processes but those are OS provided. There is no process that isn't system and isn't package isolated. Windows has system, UWP, or arbitrary app. That latter bit is what makes this not equivalent. We could kill that third tier and it's be identical isolation promises.
110
Steve Syfuhs @syfuhs.net · 20h
Again, you're conflating isolation. An android app is equivalent to a UWP app. There is no concept of a non-uwp equivalent app on Android.
100
Steve Syfuhs @syfuhs.net · 20h
I actually don't believe that to be true. I don't think they meet that claim.
000
Steve Syfuhs @syfuhs.net · 20h
I'm saying not every single way promises it can't exploit the OS. The only way it holds its promises is through strict guarantees of app installation through vetted channels. I.e. A store.
100
Steve Syfuhs @syfuhs.net · 20h
And no, android does not protect an app's data from side loaded apps. It protects against apps side loaded a specific way.
110
Steve Syfuhs @syfuhs.net · 20h
Again, Windows has that same thing. Same semantic promises. Store app or UWP or Low IL take your pick for a name. It all comes down to how that app gets onto the device. A side loaded app is no different.
110
Steve Syfuhs @syfuhs.net · 21h
If you want the same isolation you need the same isolation. It's a two way street. Go force all apps through the store. Problem solved. That was S Mode. Worked great if you had store apps. Conversely iOS ONLY has store apps.
020
Steve Syfuhs @syfuhs.net · 21h
Okay but you keep making comparisons that aren't equivalent. We have the iOS equivalent on Windows today and it's been there since Win8. What makes iOS and Android safe is the store enforcement. The minute you side load an app all bets are off.
210
Steve Syfuhs @syfuhs.net · 21h
There is no world in which a user can touch a file that malware cannot. That is the fundamental problem.
141
Steve Syfuhs @syfuhs.net · 21h
The saying "perfect is the enemy of good" is only applicable when the thing you're trying to build is materially better than what exists today. Getting to something "good" that is materially better than today's "good enough" is a monumental undertaking.
100
Steve Syfuhs @syfuhs.net · 23h
Brb calling Witness Protection and asking if they take walkins
192
Steve Syfuhs @syfuhs.net · 23h
Wait no no no no no wait no
170
Steve Syfuhs @syfuhs.net · 23h
Jerry I need you to explain this to my wife please
190
Steve Syfuhs @syfuhs.net · 02/10/2026
You don't need debug privilege to get into an adjacent process as the same user. That alone makes this a pain in the ass to defend. AVs are an unsuitable security boundary. There's no guarantee it works, otherwise what's from saying an AV is present so no point in doing anything?
100
Steve Syfuhs @syfuhs.net · 02/10/2026
Okay but what if we gave the screwdriver a chance. First it starts with a board with a nail in it and then they build another board with an even bigger nail and then eventually the biggest board with the biggest nailll.
static.klipy.com
Kang and Kodos Laughing in Space
ALT: Kang and Kodos Laughing in Space
0471
Steve Syfuhs @syfuhs.net · 02/10/2026
In fairness to the parrot, I don't think they know what 'stochastic' means.
020
Steve Syfuhs @syfuhs.net · 02/10/2026
That's not really how process trees work. Also, you don't want to indiscriminately do that. What if process A does the Hello prompt then launches a browser? The browser has access to what? Things A had, or nothing, or everything? How long does that prompt grant? Lifetime of the app? 10 min?
100
Steve Syfuhs @syfuhs.net · 02/10/2026
Sure, why not? If someone wants to build it, more power to them.
000
Steve Syfuhs @syfuhs.net · 02/10/2026
Okay but how do you determine only browsers should read those cookies? Side note. We already have this kind of protection through normal SSO capabilities as well as WAM.
200
Steve Syfuhs @syfuhs.net · 02/10/2026
I don't specifically know, but if thats the case then we're done. We've built it and have parity. It's been that way for a decade.
000
Steve Syfuhs @syfuhs.net · 02/10/2026
I haven't looked in forever but I think they bruteforce it by prompting on every unique process.
000
Steve Syfuhs @syfuhs.net · 02/10/2026
Rogue apps in the store happen, though infrequently, and we clean them up before they cause real problems, but back to the all vs some problem. If all apps get all, that promises nothing new. If all apps only get their own, that's also useless because you need to get the passwords into that silo.
100
Steve Syfuhs @syfuhs.net · 02/10/2026
So you can say "only creds with an app identity can access creds". Alright, that's any app from the Store. We built that already. That's the IL-aware bit. But then the question is, should the app see only its own creds or all the users creds? How do you decide which apps get that privilege?
200
Steve Syfuhs @syfuhs.net · 02/10/2026
Process identity and intent is "should this process be allowed to see the raw credential"? What is the deciding factor there? That Kernel knows its PID 1234 making the call with a name of program.exe isn't very meaningful. I could create explorer.exe and all it does is siphon all the creds.
100
Steve Syfuhs @syfuhs.net · 02/10/2026
Between home and work I have 2 desktops, 2 laptops, a phone, and a tablet all used daily, not to mention the myriad of dev devices floating around. Not syncing between these would be worse than having no password manager. Yes kernel knows and you can't spoof it. That doesn't solve the problem.
210
Steve Syfuhs @syfuhs.net · 02/10/2026
Saved for posterity: syfuhs.net/adventures-i...
syfuhs.net
Adventures in Credential Manager Trivia
Credential Manager is a thing in Windows and it manages your credentials.
041
Steve Syfuhs @syfuhs.net · 02/10/2026
Can I sue them for murdering the braincells in my head after reading that
010
Steve Syfuhs @syfuhs.net · 02/10/2026
Everyone has.
010
Steve Syfuhs @syfuhs.net · 02/10/2026
"Simply" is the dead giveaway. Nothing is ever simple. VBS gives you execution, not storage. TPM gives you storage, but not portability. App identification is a universally hard problem and the thing you care about more so is intent vs identity because every signal from VTL0 to VTL1 is untrusted.
130
Steve Syfuhs @syfuhs.net · 02/10/2026
No they won't. We know this. We live this. Apple has the luxury of owning the entire stack down to the hardware. Android, nearly. Windows does not and that means it's a much harder problem because we're playing with different building blocks.
130
Steve Syfuhs @syfuhs.net · 02/10/2026
I think we have length as USHORT?
000
Steve Syfuhs @syfuhs.net · 02/10/2026
Suffice to say the UX remains. It's not a generic secret store. It shouldn't be used as one. The Windows SSO capabilities continue to be pretty solid, but as we move to a more modern world, we end up with less and less utility of it with newer protocols that aren't password-based. Ah well.
5130
Steve Syfuhs @syfuhs.net · 02/10/2026
The Cred APIs are just wrong for extended functionality. Adding properties is doable, but protected properties notsomuch. Length constraints are a big problem. The security issues I mentioned up thread couldn't be addressed at the UX layer. It needed more work.
120
Steve Syfuhs @syfuhs.net · 02/10/2026
They did a fantastic job building out the UX. It was fully functional. I used it and actually still have some records sitting in my corp credman database still. It was pretty cool. Unfortunately it never shipped because it wouldn't scale in ways we needed.
130